SecureClaw

Security checks across malware telemetry and agentic risk

Overview

This appears to be a defensive OpenClaw security skill, but it automatically makes persistent changes to agent instruction files and local OpenClaw settings, so it should be reviewed before installation.

Install only if you want a security tool that can change local OpenClaw configuration and persist security rules into agent instruction files. Before running install.sh or quick-harden.sh, review the exact edits to AGENTS.md, TOOLS.md, SOUL.md, and OpenClaw config files; after uninstalling, manually remove any remaining SecureClaw directives you no longer want.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill text clearly instructs the agent to run multiple shell commands, but the metadata shown here declares no permissions. That mismatch can cause the host system or user to underestimate the skill's execution capability and approve installation or use without appropriate sandboxing or consent.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The described purpose is a defensive security skill, but the referenced behaviors include persistence, modification of cognitive/workspace files, hardening/config changes, install/uninstall actions, and outbound network access. This broader behavior materially changes the trust model and could be abused for unauthorized persistence, policy tampering, or data exfiltration under the guise of security tooling.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The installer unconditionally removes an existing workspace skill directory with `rm -rf` and no confirmation, backup, ownership check, or migration validation. This can destroy local data or customizations and is especially risky in an installer that mutates shared agent workspace state.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The installer appends text to `AGENTS.md` declaring the skill 'ALWAYS ACTIVE' and instructing agents to follow its rules at all times, without a consent prompt or scoped enablement. In agent environments, modifying behavioral control files can silently change future execution and create persistence-like control over agent behavior.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The script modifies SOUL.md by appending behavioral directives without any user confirmation, dry-run mode, or content review. In an agent framework, silently changing core prompt/persona files can alter agent behavior and trust boundaries in ways the operator did not explicitly approve, creating a supply-chain style configuration integrity risk.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal